1. Data management, governance and privacy compliance
Data centres handle vast amounts of information, including customer data, operational data, security logs and, in some cases, personal data such as employee records or biometric access data. Data management refers to the way this information is collected, stored, used, shared and deleted. Governance means having clear ownership, accountability and rules around how data is handled.
Strong data governance helps ensure that data is accurate, secure, well-structured and processed lawfully. This includes defining who owns the data, who can access it, how long it is retained, and how it is protected from misuse or unauthorised disclosure.
Privacy compliance is especially important where personal data is involved. Operators need to demonstrate that they process information transparently, lawfully and proportionately. For clients, this provides reassurance that their data and their customers’ data are being handled responsibly.
2. ISO27001:2022 framework
ISO27001:2022 is a globally recognised standard for information security. It provides a structured way to establish, maintain and continually improve an Information Security Management System (ISMS). In simple terms, an ISMS is a set of policies, processes, controls and responsibilities that an organisation uses to manage information security risks.
For data centres, ISO27001:2022 is highly relevant because it addresses both physical and digital security. This can include:
- Physical infrastructure, such as server rooms, access controls and environmental controls
- Digital assets, such as networks, systems, applications and data
- Operational processes, including change management, incident response and supplier management
- People and governance, including training, accountability and risk management
Achieving ISO27001:2022 certification can help data centre operators demonstrate that they have robust controls, clear governance, documented incident and recovery procedures, and a culture of continuous improvement.
Forvis Mazars can support organisations throughout the certification journey, from readiness assessments and gap analysis through to control design, implementation support and preparation for external audit.
3. NIS2 compliance
The Network and Information Security Directive 2 (NIS2), is the European Union’s (EU) updated cybersecurity directive. Its purpose is to strengthen the resilience of critical infrastructure and essential digital services across the EU.
Data centres are highly relevant under this type of regulation because they support critical systems and services for multiple sectors. A disruption at a data centre can have consequences far beyond the facility itself, potentially affecting financial services, healthcare, public services, digital platforms or national infrastructure.
NIS2 places emphasis on areas such as cybersecurity risk management, incident reporting, supply chain security, business continuity and governance accountability. For data centre operators, compliance is not simply about meeting a regulatory requirement. It is also about showing customers that cyber resilience is embedded into the way the organisation operates.
Forvis Mazars can help operators understand their obligations, assess current maturity, identify gaps and develop a practical compliance roadmap.
4. SOC2
System and Organisation Controls 2 (SOC2) is an independent assurance report that evaluates whether a service provider has effective controls in place. It is based on the trust services criteria developed by the American Institute of Certified Public Accountants.
The criteria cover:
- Security: protecting systems and data from unauthorised access
- Availability: ensuring systems are available for use as agreed
- Processing integrity: ensuring systems process information accurately and completely
- Confidentiality: protecting sensitive information
- Privacy: handling personal information appropriately
For data centre operators, SOC2 provides customers with independent assurance that key controls are designed and operating effectively. This can be particularly valuable when serving enterprise clients that require formal evidence before onboarding a supplier.
5. Cyber penetration testing
Cyber penetration testing, often called “pen testing”, is a controlled and ethical security assessment. Skilled testers simulate real-world cyberattacks to identify weaknesses before malicious actors can exploit them.
Unlike automated vulnerability scanning, penetration testing uses human expertise, threat intelligence and scenario-based techniques. It can assess networks, applications, systems, remote access points and, where appropriate, physical security layers.
For data centres, regular penetration testing provides practical insight into whether security controls are working as intended. It can help identify vulnerabilities that could lead to breaches, outages or service disruption. It also demonstrates to customers, insurers, investors and partners that the operator takes a proactive approach to security validation.
6. Red teaming
Red teaming goes a step further than penetration testing. While pen testing typically focuses on finding technical vulnerabilities, a red team exercise tests the organisation’s end-to-end ability to detect, respond to and recover from realistic attacks.
A red team simulates the tactics, techniques and procedures used by sophisticated threat actors. This may include:
- Attempts to exploit networks, systems or privileged accounts
- Testing whether monitoring and security operations teams detect suspicious activity
- Physical security scenarios, such as tailgating or access control bypass attempts
- Social engineering, such as phishing, impersonation or phone-based deception
- Testing incident escalation and response procedures
For a data centre, this is especially valuable because resilience depends on people, processes and technology working together. Red teaming helps identify not only technical weaknesses, but also gaps in awareness, decision-making, escalation and crisis response.
7. AI readiness
Artificial intelligence is becoming increasingly important in data centre operations. AI can support predictive maintenance, energy and cooling optimisation, capacity forecasting, intelligent automation and operational insight across multiple sites.
For example, predictive maintenance uses data to anticipate equipment failures before they happen. Cooling optimisation uses analytics to reduce energy consumption while maintaining safe operating temperatures. These capabilities can reduce downtime, improve reliability and support more efficient use of resources.
However, AI must be implemented responsibly. Data centre operators need suitable data foundations, clear governance and controls to ensure that AI models are transparent, secure, reliable and aligned with ethical and regulatory expectations. AI readiness therefore looks not only at technology, but also at governance, risk management, data quality and accountability.
8. EU DORA compliance
The Digital Operational Resilience Act (DORA) is an EU regulation focused on strengthening digital operational resilience in the financial sector. It applies to financial entities such as banks, insurers, investment firms and payment providers, as well as certain information and communications technology service providers that support them.
For data centres hosting or supporting financial workloads, DORA is particularly important. It focuses on areas such as ICT risk management, incident reporting, resilience testing, third-party risk and continuity planning.
In practical terms, DORA requires organisations to show that they can withstand, respond to and recover from technology-related disruptions. For data centre operators serving financial services clients, alignment with DORA can become a key market expectation.
9. ESG
ESG stands for environmental, social and governance. It refers to the standards that guide how an organisation operates responsibly and sustainably.
For data centres, the environmental dimension is especially important. Facilities consume significant amounts of power and water, and customers increasingly want to understand how operators manage energy efficiency, carbon impact, cooling, construction methods and renewable power strategies.
The social dimension considers the impact on employees, supply chains and local communities. The governance dimension focuses on transparency, ethical decision-making, compliance, risk management and accountability.
A credible ESG approach helps data centre operators demonstrate that they are not only building digital infrastructure but doing so responsibly and with long-term sustainability in mind.
The data centre market is becoming more sophisticated, more regulated and more competitive. Customers want confidence that the facilities they rely on are secure, resilient, compliant, sustainable and well governed. Investors and partners want evidence that risks are understood and managed. Regulators want assurance that critical infrastructure can withstand disruption.
A comprehensive assurance and accreditation framework helps bring these requirements together. By addressing data governance, ISO27001, NIS2, SOC2, penetration testing, red teaming, AI readiness, DORA and ESG, data centre operators can build a stronger foundation for trust and market credibility.
Forvis Mazars supports organisations in navigating this complexity, combining technical, regulatory, assurance and risk expertise into a practical framework. For data centre developers and operators, the opportunity is clear: assurance is no longer just a compliance exercise, it is a strategic differentiator.
Get in touch with our Energy and Infrastructure experts |
This website uses cookies.
Some of these cookies are necessary, while others help us analyse our traffic, serve advertising and deliver customised experiences for you.
For more information on the cookies we use, please refer to our Privacy Policy.
This website cannot function properly without these cookies.
Analytical cookies help us enhance our website by collecting information on its usage.
We use marketing cookies to increase the relevancy of our advertising campaigns.
